Legal
Privacy Policy
Last updated: 2026-04-26
This policy describes how ELAYGENT handles visitor and customer data. For healthcare customers, the signed customer agreement (DPA / BAA where applicable) governs the handling of protected health information; where the agreement and this page diverge, the agreement controls.
Who this applies to
This policy describes how ELAYGENT handles two kinds of data:
- Visitor data — people who visit the public marketing site or sign in to a portal account.
- Customer data — data processed on behalf of a clinic that uses ELAYGENT, including patient names, phone numbers, appointment times, and call transcripts. ELAYGENT processes customer data as a service provider; the clinic is the data controller / covered entity.
What we collect
Visitor data
- Account information you provide: email, name, role, and secured sign-in credentials.
- Optional OAuth identifiers from Google or Apple if you sign in with those providers.
- Diagnostic logs, error reports, and product analytics, all limited to what is needed to operate and improve the service.
Customer data (PHI-adjacent)
- Caller phone number, caller name as given on the call.
- Call transcripts and AI-generated summaries; call recordings or recording URLs may be stored when a location's voice-provider configuration records calls.
- Booking-intent metadata: requested appointment time, service, clinician, location.
- Where a clinic configures it: appointment status, reschedule / cancellation history, missed-call recovery outcomes.
ELAYGENT does NOT collect payment-card details directly, full patient charts, medical history, prescriptions, diagnoses, or imaging.
How we use it
Customer data is used solely to deliver the service the clinic has configured: answering calls, capturing booking intent, generating recovery follow-ups, syncing approved data to the clinic's PMS / calendar, and populating operator dashboards. Visitor data is used to provide the portal, send transactional emails, and detect abuse.
ELAYGENT does NOT sell customer data. ELAYGENT does NOT use customer data to train external models. ELAYGENT does NOT use customer data for advertising.
Service providers
ELAYGENT uses carefully selected service providers to support voice, messaging, payments, identity, hosting, and product operations. Current vendor diligence and BAA posture are shared with qualified Premium and Custom customers and reviewers under NDA. Request them at Security & Trust.
Security
ELAYGENT uses encryption in transit and at rest, clinic data isolation, role-based access, audit visibility, and abuse protections. ELAYGENT is not SOC 2 certified and is not HIPAA certified. Qualified Premium and Custom implementations can be evaluated for BAA support through customer contracting; the executed agreement and full processing chain define scope. Qualified reviewers can request implementation evidence through the Security & Trust page.
Retention
Per-workspace retention windows for call transcripts, recordings, and system activity records are configurable by a workspace admin; automated deletion of expired artifacts is opt-in per workspace and every retention sweep is recorded. Access to call transcripts and recordings is permission-gated and audited. Clinics can also configure recording opt-out per location. On account termination, customer data export and deletion follow the signed customer agreement and applicable privacy terms.
Your rights
If you are a patient whose data may have been processed by ELAYGENT on a clinic's behalf, contact the clinic directly for access, correction, or deletion of your records — the clinic is the data controller / covered entity and has the relationship with you.
If you are a portal user (clinic operator), you can update or delete your portal account by contacting your practice administrator or privacy@elaygent.com.
Children
ELAYGENT's service is not directed at individuals under 13. Where a clinic uses ELAYGENT in a pediatric context, the clinic is responsible for parental-consent compliance under applicable law.
International transfers
ELAYGENT operates primarily in the United States. Some service providers may process data in other regions as permitted by the applicable customer agreement and data-processing terms.
Changes
ELAYGENT may update this policy from time to time. Material changes that affect customer data handling require notice to the customer per the signed agreement.
Contact
Privacy questions: privacy@elaygent.com.